Back to Newsroom
Threat Intel

Fake ChatGPT, Gemini and Claude Ad Portals Are Stealing Logins

A human-operated phishing platform is impersonating advertising dashboards for ChatGPT, Gemini, Claude and other AI tools to harvest business ad-account passwords and MFA codes in real time.

Fake ChatGPT, Gemini and Claude Ad Portals Are Stealing Logins

A phishing operation posing as official advertising dashboards for ChatGPT, Google Gemini, Anthropic Claude, Perplexity, Meta's Muse and Manus is harvesting business ad-account logins — passwords and one-time MFA codes included — in real time.

What happened

Security researchers uncovered a human-operated phishing platform built around a single call to action: "Connect." Each fake product page is styled convincingly to match the real brand and promises something agency staff and media buyers would want: a weekly ads performance brief, manager-account linking, spend audits, or a "private" platform integration.

Clicking Connect opens what looks like a native browser login window — but it is drawn entirely inside the page itself, a technique known as browser-in-the-browser (BitB). Victims type their real credentials and MFA codes into this fake window, believing they are signing into Google or another identity provider.

Behind the scenes, the victim's device is fingerprinted and the captured data streams to the attackers over a live connection, letting a human operator attempt to sign into the real account immediately — before the one-time code expires.

Victims typically reach these pages through fake invitation emails impersonating the AI brands themselves. The fake portals share a common technology stack and backend infrastructure, and sit inside a larger operation that also runs Google Ads refund scams and fake recruitment sites for well-known consumer brands.

Why it matters

The target isn't just a password — it's a live advertising account, often a manager-level account controlling many linked clients. Once inside, attackers typically add their own administrators and lock out the legitimate owner, so recovery can take weeks or months rather than hours. For agencies, the damage doesn't stop at one account: it reaches every client whose ads run through it. Accounts with a clean spend history are especially valuable, since attackers either burn through the ad budget directly or resell the account on criminal marketplaces.

This fits a broader pattern of threat actors targeting the AI tooling and ad-tech accounts that marketing and growth teams rely on daily, precisely because those accounts carry both budget and trust.

What to do

  • Enable phishing-resistant authentication (hardware security keys or passkeys) on ad platform and manager accounts wherever it's supported — a BitB window cannot phish a physical key.
  • Treat "connect your AI assistant" invitations for advertising tools with the same scrutiny as any unsolicited login request: verify the sender domain and navigate to the platform directly instead of clicking email links.
  • Review advertising account activity regularly for unexpected admin additions or ownership changes, and turn on alerts wherever the platform supports them.
  • Before linking any third-party AI integration to a business ad account, confirm it through the vendor's own official dashboard rather than a link from an email or ad.
SHARE